Skip to content

Drop CN-ID (Common Name) validation per RFC 9525 Service Identity in TLS #254

@jsoref

Description

@jsoref

Appendix A. Changes from RFC 6125

The server identity can only be expressed in the subjectAltNames extension; it is no longer valid to use the commonName RDN, known as CN-ID in [VERIFY].

Honoring this RFC will fix the poor error message in:

"does not match address (neither server's domain nor IP in certificate's CN or SAN)");

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions